Due Diligence and Ongoing Monitoring

 View Only
  • 1.  Insurance due diligence

    This message was posted by a user wishing to remain anonymous
    Posted 11-25-2020 11:58 AM
    This message was posted by a user wishing to remain anonymous

    Hello,

    I'm wondering how everyone handles their insurance due diligence task.  Do you only review insurance during regular reviews or do you request and update coverages as the insurance expires?

    Thank you!


  • 2.  RE: Insurance due diligence

    Posted 11-25-2020 02:32 PM
    Along with reviewing the coverages during the initial onboarding, with key vendors we add contractual language to request they provide a Certificate of Insurance annually.


  • 3.  RE: Insurance due diligence

    Posted 12-07-2020 10:41 AM
    We review as part of our annual review, not when COI expire.  My preference is to link the annual review to the approximate date I expect the next SOC review to be available versus when COI expires.  In the absence of SOC review, I try to link annual review to date most recent annual financials available if fiscal year other than calendar.​


  • 4.  RE: Insurance due diligence

    This message was posted by a user wishing to remain anonymous
    Posted 02-03-2021 06:10 PM
    This message was posted by a user wishing to remain anonymous

    Hi Michelle,

    What type of review do you do on the COI itself?  Is this review completed by TPRM or vendor relationship manager?


  • 5.  RE: Insurance due diligence

    Posted 02-04-2021 08:19 AM
    We have all aspects of the due diligence review including COI review done within vendor management.  I look to make sure expected normal course of business insurance in place (workers comp etc), take a look at the limits and look for additional insurance coverage like cyber.  We don't have insurance minimums in place but looking at adding a contractual requirement to have cyber insurance for critical vendors with high data confidentiality risks as believe this is a best practice.​